Privacy Policy

Privacy Policy

RewardLab Pty Ltd (ABN: 24 693 431 122) ("we", "us" or the "Company") is committed
to protecting your privacy. The RewardLab platform, available as a mobile application and
through a web-based HR administrator portal (together, the "Platform"), is operated by
RewardLab Pty Ltd. This privacy policy ("Privacy Policy") describes how we manage
personal information collected through the Platform and safeguard your privacy. If you would
like more information, please contact us.

This Privacy Policy forms part of, and is subject to the provisions of, our Terms of Service (https://www.rewardlab.com.au/terms-of-service).

We care about your privacy:
At RewardLab, we are committed to protecting your personal information. We use
appropriate security measures to ensure your data is safe and accessed only by
authorised personnel. Your privacy is important to us, and we strictly follow all relevant
privacy laws and regulations to keep your information secure.

The Australian Privacy Principles

We will treat all personal information in accordance with any and all obligations that are
binding upon us under the Privacy Act 1988 (Cth) ("Privacy Act"). The Privacy Act lays
down 13 key principles in relation to the collection and treatment of personal information,
known as the "Australian Privacy Principles".


What is "personal information"?

Personal information held by the Company may include your:
• name and date of birth;
• residential and business postal addresses, telephone/mobile numbers and email
addresses;
• employment information, including your employer's name and your employee status;
• any information that you provide to us when registering for or using the Platform;
• preferences, account credentials, and device information used to access the
Platform; and
• information provided in connection with financial or insurance product enquiries or
applications made through the Platform, including information about your financial
circumstances.


How we may collect your personal information

We only collect personal information that is necessary to provide the Platform and the
services available through it, which includes enabling users to:
• register for and access the Platform;
• access employee benefits including rewards, wellbeing, insurance, and financial
products; and
• receive push notifications about relevant products, offers, and Platform updates.

Information that you provide to us

We may collect personal information that you provide to us when you:
• self-register for a Platform account;
• complete your profile or update your account details;
• apply for or enquire about insurance, financial products, or other benefits available
through the Platform;
• interact with customer support; or
• send us an email or other communication.
We do not receive a list of employees from your employer. You register for the Platform
directly.


Information collected automatically

When you use the Platform, we may automatically collect certain technical information,
including:
• device identifiers and mobile device information;
• operating system and app version;
• usage data and engagement activity on the Platform; and
• Internet Protocol (IP) addresses, for security and session management purposes.
We do not collect precise location data from your device.

Push notifications

With your consent, we may send you push notifications through the Platform. You can
manage your push notification preferences at any time through your device settings or within
the Platform.


Cookies and analytics

The web-based HR administrator portal uses "cookies" to help personalise your online
experience. A cookie is a text file placed on your hard disk by a web page server to identify
and interact more effectively with your computer. Cookies cannot be used to run programs
and are uniquely assigned to you.

You can configure your internet browser to accept all cookies, reject all cookies, or notify you when a cookie is sent. If you choose to decline cookies, you may not be able to fully experience certain features of the portal.


Why we use cookies

We use cookies in order to:
• remember your preferences for using this site;
• manage the sign-up process when you create an account;
• recognise you as logged in while you remain so; and
• remember details of data that you choose to submit to us.

Third party cookies

In some cases, third parties may place cookies through the portal. For example:
• Google Analytics may use cookies to collect de-identified data about how long users
spend on the portal and the pages that they visit; and

• third party social media applications may use cookies in order to facilitate social
media buttons or plugins.

How we may use your personal information

Your personal information may be used in order to:
• verify your identity;
• create and manage your Platform account;
• respond to any queries or feedback that you may have;
• facilitate your access to employee benefits, rewards, wellbeing, insurance, and
financial products available through the Platform;
• facilitate your access to novated leasing services provided through Leaselab Pty Ltd;
• send you push notifications about relevant products and Platform updates (with your
consent);
• conduct research and development in respect of our services;
• improve the relevance and effectiveness of our advertising and marketing activities;
and
• maintain and develop our business systems and infrastructure, and for any other purpose reasonably considered necessary or desirable by the Company in relation to the operation of the Platform and our business.

From time to time we may contact you with news, information, and offers relating to our own
services or those of selected partners. You can unsubscribe from such communications at
any time.


When we may disclose your personal information

For the purposes set out above, the Company may disclose your personal information to
organisations outside the Company. Your personal information may be disclosed to these
organisations only in relation to the Platform, and the Company takes reasonable steps to
ensure that these organisations are bound by confidentiality and privacy obligations in
relation to the protection of your personal information.

Service providers

These organisations may carry out or provide:
• customer support and enquiries;
• mailing and notification systems;
• information technology services;
• marketing, advertising, and analytics services; and
• platform usage analysis.

All third party service providers engaged by RewardLab are based in Australia.

Product providers

Where you click through from the Platform to a third party product provider (for example, an insurer, lender, or financial services provider), you will be interacting directly with that provider and their own privacy policy will apply to your interaction.

We may receive a commission or referral fee from product providers in connection with
products accessed through the Platform.

Employer reporting

We may share engagement data with your employer, including information about Platform
usage, login activity, and participation in benefit programs. We do not share the details of
any specific financial product applications or arrangements with your employer without your
consent. We do not share individually identifiable financial or insurance information with
employers. Product providers do not have access to aggregated or anonymised user data.

Novated leasing

Where you access novated leasing services through the Platform, you will be linked through
to the Leaselab platform operated by Leaselab Pty Ltd. Leaselab's own privacy policy will
apply to personal information you provide in connection with novated leasing enquiries or
applications.


Other disclosures

We may also disclose your personal information to:
• your authorised representatives or legal advisers (when requested by you to do so);
• our professional advisers, including our accountants, auditors and lawyers;
• government and regulatory authorities and other organisations, as required or
authorised by law;
• organisations who manage our business strategies, including those involved in a
transfer or sale of all or part of our assets or business; and
• the police or other appropriate persons where your communication suggests possible
illegal activity or harm to others.


Financial and insurance products

The Platform may feature financial and insurance products, including (without limitation)
insurance products (such as health, life, and income protection insurance), personal loans,
credit cards, and buy now pay later facilities. These products are provided by third party
product providers and not by RewardLab.

When you apply for or enquire about a financial or insurance product through the Platform,
relevant personal information (which may include information about your financial
circumstances, employment, and health) may be collected and used by the relevant product
provider in accordance with their own privacy policy and applicable law.

Storage and security of your personal information

We are committed to maintaining the confidentiality of the information that you provide to us
and we will take all reasonable precautions to protect your personal information from
unauthorised use or alteration.

Firewalls, anti-virus software, and email filters, as well as passwords, protect all of our
electronic information. We take all reasonable measures to ensure the security of your
personal information.


What happens to your data when you leave your employer

If your employment with your employer ends, or your employer's agreement with RewardLab
is terminated, your personal information will remain in our systems unless and until you
request deletion. You may request deletion of your personal information by contacting us
using the details set out below.

Third party websites, advertising, and marketing services

You may click through to third party websites and apps from the Platform, in which case we
recommend that you refer to the privacy policy of those websites. This Privacy Policy applies
to the Platform only and the Company assumes no responsibility for the content of any third
party websites.


Remarketing

We may use the Google Ads and/or Meta (Facebook) remarketing services to advertise on
third party websites to previous visitors to the Platform based upon their activity on the
Platform. Google and Meta may use cookies and/or pixel tags to achieve this. Any data so
collected by Google and/or Meta will be used in accordance with their own respective
privacy policies. None of your personal Google and/or Meta information is reported to us.

Preferences for third party advertising and marketing services

You can set preferences for how Google advertises to you using the Google Ads Settings
page (accessible at https://www.google.com/settings/ads). Meta has enabled an AdChoices
link that enables you to opt out of targeted advertising.


Contacting us about privacy

If you would like more information about the way we manage personal information that we
hold about you, or are concerned that we may have breached your privacy, please contact
us by email at hello@rewardlab.com.au.


Access to your personal information

In most cases, you may have access to personal information that we hold about you. We will
handle requests for access to your personal information in accordance with the Australian
Privacy Principles. All requests for access must be directed to the Privacy Officer by email or
by writing to us at our postal address. We will deal with all requests for access as quickly as
possible. We may charge you a fee for access if a cost is incurred by us in order to retrieve
your information, but in no case will we charge you a fee for your application for access.
In some cases, we may refuse to give you access to personal information that we hold about
you. This may include circumstances where giving you access would:

• be unlawful;
• have an unreasonable impact on another person's privacy; or
• prejudice an investigation of unlawful activity.

If we refuse to give you access, we will provide you with reasons for our refusal.

Correcting your personal information

We will amend any personal information about you that is held by us and that is inaccurate,
incomplete, or out of date if you request us to do so. If we disagree with your view about the
accuracy, completeness, or currency of a record, and you ask us to associate with that
record a statement that you have a contrary view, we will take reasonable steps to do so.

Complaints in respect of this Policy

If you have a complaint in respect of this policy please contact us using the details set out
above. We aim to respond to all complaints within 10 business days.


Changes to this Privacy Policy

From time to time, it may be necessary for us to revise this Privacy Policy. Any changes will
be in accordance with any applicable requirements under the Privacy Act and the Australian
Privacy Principles. We may notify you about changes to this Privacy Policy by posting an
updated version on the Platform.


If you require any further information about the Privacy Act and the Australian Privacy Principles, you
can visit the Federal Privacy Commissioner's website at www.privacy.gov.au.